h2o.ai
Attack Intelligence
h2o.ai was compromised in a ransomware attack attributed to linkc in January 2025. The organization, operating in the Technology sector in United States, was added to the group's data leak site as part of an extortion campaign.
linkc operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
As a result of our operation, we have discovered the following concerning data: 1. Unanonymized customer datasets intended for AI training. 2. Full source code of programs from the Git repository, including code for driverless systems, GPT models, and others. 3. A substantial amount of internal information, including contracts, customer personal data, project costs, and project documentation. 4. Backup copies of employee email accounts containing customer correspondence.